Solutions / Security & CISO
Information Security

Beat the CERT-In six-hour clock — and prove your logs are in India.

CERT-In directions hit ICT and data-centre operators directly: reportable cyber incidents must reach CERT-In within six hours of detection, and system logs must be retained for 180 days within India. Praman runs those checks continuously and drives the 6-hour clock with a visible countdown the security team cannot miss.

The problems we hear from information security teams

  • ▹Six-hour CERT-In reporting window tracked manually under incident stress
  • ▹Uncertainty about whether log retention meets 180 days, in-country
  • ▹Security safeguards (encryption-at-rest, access control) unevidenced per asset
  • ▹Clock-sync and operational hygiene checks slip between teams

What Praman does for you

6-hour incident countdown

Cyber-reportable incidents start a prominent CERT-In clock; every notification step is recorded as evidence.

Log-retention assurance

Verifies log-bearing assets retain ≥180 days and sit in India; flags any gap by asset.

Safeguard checks

Confirms assets holding personal data carry encryption-at-rest and access-control safeguards.

Advisory by design

Praman observes, verdicts and logs — it never blocks live traffic, so security keeps full control.

Obligations you’ll see covered

Each maps to an automated check with its statutory citation and tamper-evident evidence.

CERTIN-INCIDENT-6H6-hour incident reportingCERTIN-LOGS-180D180-day log retention in IndiaCERTIN-NTPClock synchronisationDPDP-SECURITYReasonable security safeguards

Frequently asked

Does Praman send the CERT-In report automatically?

No. Praman pre-fills an editable draft and tracks the clock; sending is a deliberate human action. It never auto-sends regulator notifications.

How is the 6-hour window calculated?

From the recorded detection time of an incident flagged as cyber-reportable. The countdown is shown live and every step is audit-logged.